CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Music Sheet Viewer WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Music Sheet Viewer plugin for WordPress, affecting all versions through 4.1. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'pn_msv' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
WP Post List Table Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Post List Table plugin for WordPress, affecting all versions through 1.0.3. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'wpb_post_list_table' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
WordPress Table Editor Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Table Editor plugin for WordPress, affecting all versions through 1.5.1. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'wptableeditor_vtabs' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
ECPay Ecommerce for WooCommerce Missing Authorization Vulnerability Allowing Log Deletion
A vulnerability exists in the ECPay Ecommerce for WooCommerce plugin for WordPress, in all versions through 1.1.2411060. The issue arises from a lack of proper capability checks on the 'clear_ecpay_debug_log' AJAX action. This flaw enables authenticated attackers with Subscriber-level access or higher to delete the plugin's log files, leading to unauthorized data loss.
WordPress Single-User Chat Plugin Data Modification Vulnerability Leading to Denial-of-Service
A vulnerability exists in the Single-user-chat plugin for WordPress, all versions through 0.5, allowing authenticated attackers with subscriber-level access and above to unauthorizedly modify data. The issue arises from inadequate validation in the 'single_user_chat_update_login' function, enabling attackers to change option values to 'login'. This could disrupt normal site operations by introducing errors that affect legitimate users or by altering settings related to user registration. Such changes could potentially be exploited to cause a denial-of-service condition on the site.
WordPress Survey & Poll Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress Survey & Poll plugin, specifically in versions through 1.7.5. The issue arises from inadequate escaping of user-supplied data in the 'id' attribute of the 'survey' shortcode, allowing authenticated attackers with Contributor-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive information in the database.
All Bootstrap Blocks WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the All Bootstrap Blocks plugin for WordPress, affecting all versions through 1.3.26. The issue arises in the 'Accordion' widget, where inadequate input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts. These scripts are executed when a user accesses the affected page.
Wonder FontAwesome WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wonder FontAwesome plugin for WordPress, affecting all versions through 0.8. The vulnerability arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject malicious scripts. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
WE Testimonial Slider Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WE – Testimonial Slider plugin for WordPress, affecting all versions through 1.5. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into testimonial author names. The injected scripts are executed when users view the affected testimonials.
Kona Gallery Block Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Kona Gallery Block plugin for WordPress, specifically in the 'Kona: Instagram for Gutenberg' Block. The issue resides within the 'align' attribute and affects all versions through 1.7. The vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages. These scripts would execute when a user accesses the compromised page.
Stockdio Historical Chart WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Stockdio Historical Chart plugin for WordPress, affecting all versions through 2.8.18. The vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly within the 'stockdio-historical-chart' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
W2S Migrate WooCommerce to Shopify Plugin Arbitrary File Read Vulnerability
A vulnerability allowing arbitrary file read has been identified in the W2S – Migrate WooCommerce to Shopify plugin for WordPress, affecting all versions through 1.2.1. The issue arises from the 'viw2s_view_log' AJAX action, which lacks proper authorization. This vulnerability enables authenticated attackers with Subscriber-level access and above to read arbitrary files on the server, potentially exposing sensitive information.
Media Manager for UserPro Missing Authorization Vulnerability Allowing Privilege Escalation
A vulnerability exists in the Media Manager for UserPro plugin for WordPress, all versions through 3.11.0, allowing unauthorized data modification that could lead to privilege escalation. The issue arises from a missing capability check in the add_capto_img() function, enabling unauthenticated attackers to update arbitrary options on the WordPress site. This vulnerability could be exploited to change the default registration role to administrator and activate user registration, granting administrative access to the attacker on the compromised site.
Media Manager for UserPro Missing Authorization Vulnerability in WordPress
A vulnerability exists in the Media Manager for UserPro plugin for WordPress, affecting all versions through 3.12.0. The issue arises from a lack of proper capability checks in the upm_upload_media() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly modify data. This vulnerability can be exploited to change arbitrary options on the WordPress site, such as updating the default role for new users to administrator and enabling user registration, potentially granting administrative access to the attacker.
HTML5 Chat WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HTML5 Chat plugin for WordPress, affecting all versions through 1.04. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'HTML5CHAT' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
WP Dispensary Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WP Dispensary plugin for WordPress, affecting all versions through 4.5.0. The issue arises from inadequate input sanitization and output escaping on user-supplied attributes in the 'wpd_menu' shortcode. This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary scripts into pages, which are executed when users access the affected pages.
WordPress Team Rosters Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Team Rosters plugin for WordPress, affecting all versions through 4.7. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if the attacker successfully persuades a user to perform an action, such as clicking a link.
System Dashboard WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the System Dashboard plugin for WordPress, affecting all versions through 2.8.17. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could execute if an administrative user is tricked into clicking a link or performing a similar action.
Safe Ai Malware Protection for WP Missing Authorization Vulnerability Allowing Unauthenticated Database Export
A vulnerability exists in the Safe Ai Malware Protection for WP plugin for WordPress, in all versions through 1.0.17. The issue arises from a lack of proper capability checks in the export_db() function, allowing unauthenticated attackers to access and download a complete dump of the site's database.
Ai Image Alt Text Generator for WP Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Ai Image Alt Text Generator for WP plugin for WordPress, affecting all versions through 1.0.6. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'page' parameter. These scripts could be executed if a user is tricked into clicking a link.
Royal Core WordPress Plugin Privilege Escalation Vulnerability
A vulnerability in the Royal Core plugin for WordPress allows for unauthorized data modification that could lead to privilege escalation. This issue arises from a missing capability check in the 'royal_restore_backup' function, affecting all versions up to and including 2.9.2. As a result, authenticated attackers with Subscriber-level access or higher can manipulate arbitrary options on the WordPress site. This vulnerability could be exploited to change the default role for new users to administrator and enable user registration, allowing attackers to gain administrative access on the site.
Typer Core WordPress Plugin Information Exposure Vulnerability
A vulnerability allowing information exposure exists in the Typer Core plugin for WordPress, affecting all versions through 1.9.6. The issue arises from inadequate restrictions on which posts can be included via the 'elementor-template' shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract data from private or draft posts created with Elementor, which they should not be able to view.
Borderless WordPress Plugin Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the Borderless WordPress plugin, specifically in the 'write_config' function. This issue affects all versions of the plugin up to and including 1.6.0. The vulnerability arises from inadequate sanitization of an imported JSON file, allowing authenticated attackers with Administrator-level access to execute arbitrary code on the server.
Borderless WordPress Plugin Missing Authorization Vulnerability in Icon Font Deletion
A vulnerability exists in the Borderless WordPress plugin, specifically in the 'remove_zipped_font' function, all versions through 1.5.9. The issue arises from a lack of proper capability checks, allowing authenticated attackers with Subscriber-level access or higher to delete previously uploaded icon fonts. This unauthorized data loss could impact users relying on custom icon packs for their WordPress sites.
Storely WordPress Theme Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Storely theme for WordPress, affecting all versions through 18. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts. These scripts execute when users access the compromised pages.
MWB HubSpot for WooCommerce Privilege Escalation Vulnerability
A vulnerability in the MWB HubSpot for WooCommerce plugin, specifically in versions through 1.5.9, allows authenticated users with Contributor-level access and above to bypass authorization checks and modify arbitrary data. This could lead to privilege escalation by enabling these users to change the default role of new users to administrator, potentially giving them full administrative access on the site.
Axiomatic Bento4 Heap-Based Buffer Overflow Vulnerability in AP4_DataBuffer::GetData
A critical heap-based buffer overflow vulnerability has been identified in Axiomatic Bento4 versions through 1.6.0-641. The issue arises in the function AP4_DataBuffer::GetData within the library Ap4DataBuffer.h. This vulnerability can be exploited remotely, although the complexity of the attack is high and the exploitation is known to be difficult.
Cianet ONU GW24AC Cross-Site Scripting Vulnerability in Login Component
A cross-site scripting (XSS) vulnerability has been identified in the Cianet ONU GW24AC model, in versions prior to 20250127. The issue arises in the Login component, where the browserLang parameter can be manipulated to inject malicious scripts. This vulnerability can be exploited remotely and requires user interaction.
Automatically Hierarchic Categories in Menu WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Automatically Hierarchic Categories in Menu plugin for WordPress, affecting all versions through 2.0.7. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'autocategorymenu' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
Alex Reservations Smart Restaurant Booking Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Alex Reservations: Smart Restaurant Booking plugin for WordPress, affecting all versions through 2.0.5. The issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the plugin's 'rr_form' shortcode. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which are executed when users access the affected pages.
EmbedAI Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability exists in EmbedAI versions prior to 2.1. This vulnerability allows authenticated attackers to inject malicious JavaScript into messages, which is executed when the chat is opened by a user.
EmbedAI Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability exists in EmbedAI versions through 2.1. This issue allows authenticated attackers to create malicious URLs that inject JavaScript code, which is executed when a user clicks the link. The vulnerability is present in the '/embedai/users/show/<SCRIPT>' endpoint.
EmbedAI Improper Access Control Vulnerability Allowing Database Backup Retrieval
A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables authenticated attackers to access database backups by requesting the '/embedai/app/uploads/database/<SQL_FILE>' endpoint.
EmbedAI Improper Access Control Vulnerability Allowing Subscription Plan Changes
A vulnerability allowing improper access control has been identified in EmbedAI versions prior to 2.1. This issue enables authenticated attackers to change their subscription plans without payment by sending a POST request to the '/demos/embedai/pmt_cash_on_delivery/pay' endpoint with modified parameters.
EmbedAI Improper Access Control Vulnerability Allowing Information Disclosure About User Visits
A vulnerability allowing improper access control has been identified in EmbedAI versions prior to 2.1. This issue enables authenticated attackers to access the endpoint '/embedai/visits/show/<VISIT_ID>' and retrieve information about visits made by other users. The data obtained includes the IP address, user agent, and location of the users who visited the web page.
EmbedAI Improper Access Control Vulnerability Allowing File Retrieval from Other Users
A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables an authenticated attacker to access files stored by other users by modifying the 'FILE_ID' parameter in the '/embedai/files/show/<FILE_ID>' endpoint.
IBM App Connect Enterprise Certified Container Network Egress Restriction Vulnerability
A vulnerability exists in IBM App Connect Enterprise Certified Container Pods across multiple versions, including 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7. These Pods do not properly restrict network egress for internal infrastructure, allowing unnecessary external access.
EmbedAI Improper Access Control Vulnerability Allowing Message Injection in Chats
A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables an authenticated attacker to inject messages into other users' chats by manipulating the 'chat_id' parameter in the POST request to the '/embedai/chats/send_message' endpoint.
EmbedAI Improper Access Control Vulnerability Allowing Message Interception
A vulnerability allowing improper access control has been identified in EmbedAI versions prior to 2.1. This issue enables authenticated attackers to intercept chat messages from other users by manipulating the 'CHAT_ID' parameter in the '/embedai/chats/load_messages' endpoint.
EmbedAI Improper Access Control Vulnerability Allowing Unauthorized Subscription Information Disclosure
A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables an authenticated attacker to access subscription information of other users by modifying the 'SUSCBRIPTION_ID' parameter in the '/demos/embedai/subscriptions/show/<SUSCBRIPTION_ID>' endpoint.
WP Image Uploader Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the WP Image Uploader plugin for WordPress, affecting all versions through 1.0.1. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.
Contact Form & SMTP Plugin for WordPress by PirateForms Arbitrary Shortcode Execution Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the Contact Form & SMTP Plugin for WordPress by PirateForms, affecting all versions through 2.6.0. The issue arises because the plugin allows users to execute actions without proper validation, enabling unauthenticated attackers to run arbitrary shortcodes.
Clinked Client Portal Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Clinked Client Portal plugin for WordPress, affecting all versions through 1.9. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'clinked-login-button' shortcode. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will be executed when users access those pages.
Simple:Press Forum Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Simple:Press Forum plugin for WordPress, affecting all versions through 6.10.11. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link.
SonicWall NetExtender Windows Privilege Escalation Vulnerability via Unauthorized SYSTEM File Access
A vulnerability exists in the NetExtender Windows client log export function, allowing unauthorized access to sensitive Windows system files. This access could potentially lead to privilege escalation. The issue is present in NetExtender Windows version 10.3.0, affecting both 32-bit and 64-bit clients. Notably, NetExtender Windows 10.2.x versions and Linux-based NetExtender clients are not affected.
Dell NetWorker Unquoted Search Path Vulnerability Allowing Code Execution
A vulnerability allowing code execution through an unquoted search path has been identified in Dell NetWorker versions prior to 19.11.0.3, all versions of 19.10, and earlier releases. This vulnerability could be exploited by a low-privileged attacker with local access.
VR-Frases WordPress Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the VR-Frases (collect & share quotes) plugin for WordPress, affecting all versions through 3.0.1. The vulnerability arises from inadequate escaping of user-supplied parameters and insufficient preparation of the SQL query, allowing unauthenticated attackers to inject additional SQL commands. This exploitation could lead to the extraction of sensitive information from the database.
VR-Frases WordPress Plugin Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the VR-Frases (collect & share quotes) plugin for WordPress, affecting all versions through 3.0.1. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. These scripts could be executed if a user is tricked into clicking a link or performing a similar action.
Wondershare Dr.Fone Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in Wondershare Dr.Fone version 13.5.21. This issue allows an attacker to escalate privileges by replacing the binary located at 'C:\ProgramData\Wondershare\wsServices\ElevationService.exe' with a malicious version. The substituted binary is automatically executed by the SYSTEM user.
CP Contact Form with PayPal WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the CP Contact Form with PayPal plugin for WordPress, affecting all versions through 1.3.52. The vulnerability arises from inadequate nonce validation in the 'cp_contact_form_paypal_check_init_actions()' function, allowing unauthenticated attackers to manipulate discount codes by tricking an administrator into clicking a link.
